Category:
AI Governance
AI Regulation
Published date:

The short answer
Every framework asks for the same three.
A record of each AI system you run and what it is for.
Evidence of what it did, retained for at least six months.
An owner accountable for it.
The EU AI Act makes this binding for high-risk systems from December 2027, while NIST and ISO/IEC 42001 are still operating on a voluntary basis yet.
Legal position and dates sourced on 21 Aug 2026 from the Official Journal, NIST and ISO published materials. This is not legal advice. Consult counsel on how any of it applies to you.
Key takeaways
Three frameworks matter for most organisations: the EU AI Act, which is binding but scoped, plus NIST AI RMF and ISO/IEC 42001, which are voluntary.
Your first question to address is whether you are a provider or a deployer under the EU AI Act. Almost every enterprise buying AI tools is a deployer, which narrows the duties considerably.
29 US states passed 109 AI laws in the first half of 2026. Roughly 73% of Americans want AI development slowed and heavily regulated.
AI norms vary based on the risk classification of systems, but rules are not set yet. The appliedAI Institute classified 628 German AI startups in July 2026 and found 25.4% high risk, against the European Commission's own estimate of 5 to 15%. A further 69 could not be classified either way.
The gap is not awareness; it is record maintenance. Schellman found 74% of enterprises believe they are audit-ready for AI while 27% actually are. Fewer than one in five hold a complete, actively maintained inventory of which AI systems reach customer data.
That's what Guickly is solving first. It gives you one view of every AI tool, model and agent in the company. You can't regulate what you can't see.
Which frameworks apply to you?
Start here rather than with a statute. Work down the left. Each yes takes you out to what it means for you.

Two things fall out of that tree for most organisations. You are almost certainly a deployer rather than a provider, which narrows your duties considerably.
Check your own position
Our tree above gives you the shape. These tools give you the detail. All of them are free. Check any classification against the date table further down, because some published checkers still run on the old text of the Act, before the amendments explained further down.
Tool | Run by | What it does |
|---|---|---|
European Commission, AI Office | Official interactive questionnaire on scope and classification, an official Act explorer and an implementation timeline. | |
Future of Life Institute | Granular on roles. Separates provider, deployer, importer, distributor, product manufacturer and authorised representative. Flags when Article 25 turns a deployer into a provider. | |
NIST | Suggested actions against each function and subcategory, including inventory subcategory | |
ISO | The certifiable AI management system standard | |
Future of Life Institute | Plain reading of the transparency duties, which is the part that binds you today |
One thing to expect from any of them. They return an indicative classification, not a legal opinion.
Classification is also harder than the official estimates suggest. The appliedAI Institute for Europe classified 628 German AI startups in July 2026, taking the highest-risk use case for each. Of the 559 it could place, 25.4% came out high risk. The European Commission's own 2021 impact assessment had estimated 5 to 15% of AI applications would be high risk. The study says plainly that this estimate "does not apply to German AI startups". A further 26.3% landed in transparency obligations, the tier that binds today.
The other number in that study is the useful one for you. 69 of the 628 could not be conclusively classified at all, even after a human reviewed each one. The answer depended on deployment context and technical detail the reviewers could not see. If your own team disagrees about a classification, that is the normal condition, not a sign of incompetence.
That study looks at startups building AI, so it measures provider side classification rather than your position as a deployer. It is cited here to highlight how often the answer is unclear, not as an assessment on your own risk class.
Are you a provider or a deployer?
This is where most vendor content goes wrong and it changes the answer completely.
A provider develops an AI system and places it on the market. A deployer uses one under its own authority. If you are an enterprise buying Copilot, ChatGPT Enterprise, Claude, or a vendor's underwriting model, you are a deployer. Most of the AI Act falls on providers.
Obligation | EU AI Act article | Falls on | Deferred? |
|---|---|---|---|
Technical documentation, Annex IV | Art 11 | Provider | Yes |
System must log events automatically | Art 12 | Provider (design duty) | Yes |
Retain automatically generated logs, at least six months | Art 19 | Provider | Yes |
Use per instructions, human oversight, monitor operation | Art 26(1) to (5) | Deployer | Yes |
Retain logs under your control, at least six months | Art 26(6) | Deployer | Yes |
Inform workers and their representatives before use at work | Art 26(7) | Deployer | Yes |
Register use in the EU database | Art 49(3) | Deployer, public authorities only | Unresolved |
Fundamental rights impact assessment | Art 27 | Deployer, public bodies, public service providers, credit scoring and life or health insurance | Yes |
Post market monitoring plan | Art 72 | Provider | Yes |
Disclose that a person is interacting with AI | Art 50(1) | Provider | No, in force |
Mark synthetic output in machine readable format | Art 50(2) | Provider | No, in force |
Notify people exposed to emotion recognition or biometric categorisation | Art 50(3) | Deployer | No, in force |
Disclose deep fakes and AI generated text published on matters of public interest | Art 50(4) | Deployer | No, in force |
A developer needs to note that Article 25(1) turns you into a provider in three cases. You put your name or trademark on a high-risk system. You substantially modify one. Or you "modify the intended purpose of an AI system, including a general-purpose AI system" so that it becomes high risk.
Build an internal tool on a general purpose model, aim it at hiring or credit decisions and you inherit the full Article 16 provider stack.
What the three frameworks actually ask for
Three frameworks matter for most organisations. They differ on force. They converge almost completely on substance.
Framework | Applies to you if | Binding? | What it actually asks you to hold | When |
|---|---|---|---|---|
You place AI on the EU market, or your AI output is used in the EU | Yes, but scoped | Per system technical documentation, automatic event logs kept at least six months, an accountable deployer, transparency notices | Transparency now. High risk documentation and logging from 2 Dec 2027 | |
You want a recognised structure, or you sell to US federal or Texas buyers | No, voluntary | "Mechanisms are in place to inventory AI systems", resourced by risk priority (GOVERN 1.6) | Available now. Under revision | |
Your buyers ask for certification, or you need to answer their security review | No, but certifiable and contractually demanded | A defined and documented management system scope, per system technical documentation, event logs | Available now |
Two details worth knowing rather than memorising. NIST is explicit that it is voluntary: "NIST has produced the AI RMF as a voluntary Framework." But Texas TRAIGA names substantial compliance with the NIST AI RMF as a safe harbour. That is how a voluntary framework picks up legal weight without becoming law.
On ISO, one caution. No Annex A control title contains the word inventory. Clause 4.3 requires the management system scope to be documented. The per system documentation and logging controls sit in Annex A. Those Annex A numbers are behind the ISO paywall, so verify them against a purchased copy before quoting them anywhere that matters. ISO 42001 is also where commercial pressure concentrates. Its supplier control puts your vendors in scope. That is how the question travels down a supply chain and lands in your procurement questionnaire.
When the obligations land
The dates below are the current legal position. Two of them moved this year, which is why a lot of published guidance is out of date.
The reason is the Digital Omnibus. An omnibus is one law that amends several existing laws at once. The EU uses them to make housekeeping changes without reopening each act separately. This one amended the AI Act. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. Its main effect was to push the high risk regime back. The new dates are fixed, with no trigger or condition attached.
Date | What applies under the EU AI Act | Status |
|---|---|---|
1 Aug 2024 | Regulation (EU) 2024/1689 enters into force | In force |
2 Feb 2025 | Prohibited practices (Art 5), AI literacy duty (Art 4) | In force |
2 Aug 2025 | General purpose AI model obligations, governance, enforceable penalties | In force |
2 Aug 2026 | Transparency obligations (Art 50) | In force |
2 Dec 2026 | New prohibitions on non consensual intimate imagery and CSAM. Marking deadline for synthetic content systems already on the market | Pending |
2 Aug 2027 | Member State regulatory sandboxes operational | Deferred from 2 Aug 2026 |
2 Dec 2027 | High risk regime for standalone Annex III systems: risk management, technical documentation, logging, deployer duties | Deferred from 2 Aug 2026 |
2 Aug 2028 | High risk regime for AI embedded in regulated products | Deferred from 2 Aug 2027 |
Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, Official Journal, 24 July 2026.
Three things the Omnibus also did, briefly. It softened the AI literacy duty to supporting staff literacy rather than guaranteeing a level. It added the new prohibitions above. And it moved the bias detection legal basis into a new provision covering all AI systems rather than only high risk ones.
On US state law, briefly. There is no federal AI statute. Colorado repealed and replaced its AI Act with the Automated Decision-Making Technology Act, effective 1 January 2027, which keeps a three year record retention duty for developers and deployers. Texas TRAIGA has been in force since 1 January 2026 and creates no inventory duty. Beyond that it is patchwork: 29 states passed 109 AI laws in the first half of 2026 alone.
What to keep in mind when you build this
This is the part no framework document tells you. It is where organisations lose the most time.
Agree what counts as an AI system before you count anything. The EU AI Act definition is deliberately broad. It captures things teams do not think of as AI, including embedded features inside software you already bought.
Classify per system, not per company. You will be a deployer for almost everything and a provider for a handful of internal builds. The handful is what carries the real exposure, so the question is not "what are we" but "which of these are we a provider for".
Build a live record, not an audit snapshot. This is the most common failure and it is measurable. Schellman's 2026 State of AI Governance report found that 74% of enterprises believe they are audit ready for AI while only 27% actually are.
Separate research finds fewer than one in five organisations hold a complete, actively maintained inventory of which AI systems can reach customer data. More than half have no systematic inventory of AI in production at all. A spreadsheet assembled for a board meeting is out of date within a quarter. AI adoption inside a company does not move at the speed of an audit cycle.Start retention before you need it. Log retention is not retrospective. A six month minimum starting in 2028 tells you nothing about 2027.
Name a human owner for each system. Every framework here asks who is accountable.
Know what you are not required to log. This one saves money and reduces the surface are. The EU AI Act does not ask you to log prompts. It does not ask you to log outputs. It does not ask you to record which employee used which tool.
Size the exposure honestly. Penalties have been enforceable since August 2025. The tier covering deployer duties and transparency runs to €15 million or 3% of worldwide turnover, whichever is higher. Prohibited practices run to €35 million or 7%.
Do not build it only for the regulator. Procurement asks before any authority does. It asks in a form you cannot defer. The same record answers a security questionnaire, an internal audit, a board question about AI spend and, later, a compliance file.
Expect the scope to move under you. Agentic systems are the current example: 74% of organisations plan to adopt agentic AI within two years while only 21% have a mature governance model for AI agents. A record designed only around the tools you bought last year will not survive the ones arriving this year.
Is AI regulation loosening or tightening?
Read the Omnibus on its own and the answer looks like loosening. Read the room and it does not.
The deferral was fought. 133 civil society organisations and unions urged the Commission to halt the package, describing it as the biggest rollback of digital rights in EU history. European Digital Rights argued the AI file "delays key protections, weakens transparency and creates a dangerous precedent". The European Centre for Not for Profit Law published a line by line analysis calling it deregulation at the expense of fundamental rights. Whatever you make of those positions, they tell you the political settlement is not stable. Deferred dates get revisited.
The public is not asking for less. Polling through 2026 puts support for slow, heavily regulated AI development at roughly 73% of Americans. About six in ten are more worried that government will do too little than too much. Another 73% say businesses are not transparent enough about how they use AI. That is bipartisan. It is the ground politicians stand on.
Legislatures are still writing. 29 US states passed 109 AI laws in the first half of 2026. Colorado repealed and replaced its own AI Act rather than abandoning it. The replacement keeps a three year record retention duty. The pattern is not retreat. It is churn with a rising floor.

The useful way to hold this: the legal floor is low today and rising on a published schedule, while the commercial floor is already higher than the legal one. Your next enterprise deal will ask about AI governance before any regulator does.
Why the record is worth building before the deadline
Two dates moved. Nothing about what will eventually be required moved with them. The schedule is now published years in advance, which is unusual and worth using.
The reason to start early is not diligence for its own sake. It is that a record started in 2027 describes 2027 and nothing before it. Retention is not retrospective, so evidence you did not capture cannot be produced later.
And the regulator is not the first to ask. A procurement questionnaire asks which AI systems touch customer data. An auditor asks who approved the model in the underwriting flow. A board asks what the company spends on AI and what it got back. Those questions arrive before December 2027, they are asked by people who can withhold a contract rather than issue a fine. None of them can be answered from an expense report.
Guickly is the measurement layer for enterprise AI: one view of every AI tool, model and agent, what each costs and whether it works.
FAQ
Does the EU AI Act require an AI inventory? Not in those words. No article of the EU AI Act uses the word inventory. What it does require is four things. Technical documentation per high risk system under Article 11. Automatic event logging under Article 12. Log retention under Articles 19 and 26(6). Registration in the EU database under Article 49. Those duties presuppose an inventory without mandating one and most of them are now deferred to 2 December 2027.
When do EU AI Act high risk obligations actually apply? 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved both dates. Anything published before then citing 2 August 2026 is out of date.
What are enterprises legally required to track today? Under the EU AI Act, the live duties are the transparency obligations in Article 50. They took effect on 2 August 2026. Two of them bind deployers. Article 50(3) says you must notify people exposed to emotion recognition or biometric categorisation. Article 50(4) says you must disclose deep fakes and AI generated text published in the public interest. The prohibitions in Article 5 and the AI literacy duty in Article 4 have applied since 2 February 2025.
Is NIST AI RMF or ISO 42001 legally required? Neither. NIST states the AI RMF is voluntary and that organisations will not be required to use it. ISO/IEC 42001 certification is voluntary too. Both acquire practical force through contracts, procurement questionnaires and statutory safe harbours and Texas TRAIGA names substantial compliance with the NIST AI RMF as one of its safe harbours.
Do EU AI Act obligations fall on the company using AI or the company that built it? Mostly on the provider that built and placed the system on the market. A deployer using someone else's system has a shorter list, principally Article 26. A deployer becomes a provider under Article 25(1) in three ways. By putting its own name on a high risk system. By substantially modifying one. Or by repurposing a general purpose system so that it becomes high risk.
